PoC Index

CVE-2024-1330

MEDIUM 4.3EPSS 0.4%

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.42% chance of exploitation in the next 30 days, 35th percentile
Published
2024-06-27
Updated
2025-09-15

Proof-of-concept exploits (1)

References

Related